vendor:
SOHO
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site scripting and HTML injection
79, 80
CWE
Product Name: SOHO
Affected Version From: 6.5.0.3
Affected Version To: 6.5.0.3
Patch Exists: YES
Related CWE: N/A
CPE: h:sonicwall:soho
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Multiple remote input validation vulnerabilities in SonicWALL SOHO
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks, potentially leading to a compromise of the affected device.
Mitigation:
Input validation should be performed to ensure that user-supplied input is properly sanitized prior to being included in dynamically generated Web content.